सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 6। किसी मैच की रिपोर्ट करने वाली सार्वजनिक ब्लॉक सूचियाँ: 2। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
डोमेन सुरक्षा और ख़तरे की आसूचना

rewards-heisted[.]xyz

“Heisted”

धमकी भरा फैसला गंभीर 90/100 साक्ष्य स्कोर
उपलब्धता सर्वर त्रुटि नवीनतम संग्रहीत प्रतिक्रिया अनिर्णायक थी
वायरस का कुल पता लगाना: 6/91 Spamhaus DBL: DBL_PHISH संग्रहीत ब्लॉकलिस्ट मिलान: 2 URLQuery threat systems: 1 alert घोटाले का प्रकार: Credential Phishing
28/06/2026 1 Report Sent CDN
रिपोर्ट सारांश

rewards-heisted.xyz — सर्वर त्रुटि (HTTP 502). घोटाले का प्रकार: Credential Phishing. साक्ष्य सारांश: VirusTotal 6/91 (alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, LevelBlue); URLQuery 1 alert; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 90/100. रजिस्ट्रार: NiceNIC.

मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।

साक्ष्य सारांश
आलोचनात्मक
संदर्भ
D1A868CB
स्कोर
90/100

This domain, rewards-heisted.xyz, is actively engaged in credential theft operations, presenting itself as a legitimate rewards or loyalty program to deceive users into submitting sensitive login information. The site employs social engineering tactics, likely leveraging urgency or exclusivity claims to prompt victims into entering credentials, which are then harvested for malicious purposes such as account takeover, identity theft, or further targeted attacks. The page title 'Heisted' suggests an attempt to create a false sense of urgency or legitimacy, a common tactic in phishing campaigns designed to lower user vigilance. Analysis of the domain infrastructure reveals several indicators of malicious intent. The domain was registered on June 26, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with high-risk domains. As of this report, the domain resolves to the IP address 172.67.198.169 and has not yet been flagged by security vendors, with a VirusTotal detection score of 0 out of 95. The absence of detections at this stage is not uncommon for newly registered domains, which often evade initial scrutiny due to their recent creation and lack of historical reputation. The use of a content delivery network (CDN) IP further complicates attribution and takedown efforts, as it obscures the true origin of the malicious infrastructure. Users who have visited rewards-heisted.xyz or interacted with its content are advised to take immediate remedial action. Those who entered credentials should assume compromise and initiate password resets for all accounts where the same or similar credentials were used. Enable multi-factor authentication (MFA) on critical accounts to mitigate the risk of unauthorized access. Monitor financial and communication accounts for signs of suspicious activity, such as unauthorized transactions or messages. Security teams should update blocklists to include the domain and its associated IP address, 172.67.198.169, to prevent further exposure within their networks. Reporting the domain to relevant threat intelligence platforms can aid in broader mitigation efforts and contribute to the domain's eventual takedown.

VirusTotal
VirusTotal
6 det.
URLQuery
यूआरएलक्वेरी
1 threat alert
URLScan
यूआरएलस्कैन
TLS प्रमाणपत्र
Google Trust Services / WE1
आयु
2 mo New
देखी गई स्थिति
सर्वर त्रुटि 502
PhishDestroy
विनाश सूची
सूचीबद्ध
Reports Sent
1
डेटा कवरेज VirusTotal 6 / 91 यूआरएलक्वेरी 1 threat-system alert फ़िशस्टैट्स जाँच नहीं की गई ओटीएक्स no community references सीएफ रडार no data URLScan capture संग्रहित रिपोर्ट URLScan verdict विश्लेषण पूरा हुआ डीएनएस ब्लॉक जाँच नहीं की गई TLS valid certificate, 35d कौन है 2 mo old स्क्रीनशॉट 3 captures · 3 sources चेन पुनर्निर्देशित करें जांच नहीं की गई
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
Hagezi Threat Feed rewards-heisted.xyz malicious Sinkholed
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
11/12
Sent Report Recorded
Stored sent-report record for registrar NICENIC INTERNATIONAL GROUP CO., LIMITED, hosting provider, 1 abuse contact
abuse@nicenic.net
28/06/2026

सार्वजनिक ब्लॉकलिस्ट स्थिति

सहेजा गया कैप्चर

पेज शीर्षक
Heisted
TLS प्रमाणपत्र
Valid transport encryption · जारीकर्ता Google Trust Services / WE1 · valid for 35 days

डोमेन इंटेलिजेंस

डोमेन
URLScan Verdict विश्लेषण पूरा हुआ score 0 report ↗
सर्वर / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden एज-आईपी प्रतिष्ठा इस डोमेन के लिए जिम्मेदार नहीं है।
रजिस्ट्रार NiceNIC RU(RU) PhishDestroy Investigation
दुरुपयोग संपर्कabuse@nicenic.net
IP पता 172.67.198.169 CDN
भौगोलिक स्थानCA Toronto, CA
नेटवर्कAS13335 · Cloudflare, Inc.
रिवर्स IPviewdns.info → rapiddns.io →
मूल आईपी सीडीएन प्रॉक्सी के पीछे छिपा हुआ है। किनारे के पते के लिए रिवर्स-आईपी परिणामों में असंबंधित किरायेदार शामिल हैं; मूल का पता लगाने के लिए निष्क्रिय DNS या प्रमाणपत्र-पारदर्शिता डेटा की आवश्यकता होती है।
पंजीकरणनिर्मित 26/06/2026 (54d · New) Expires 26/06/2027
HTTP स्थिति502 Error
Elapsed Since First Report 6h
हम क्या मापते हैं Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: सर्वर त्रुटि.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
पहली बार पता चला28/06/2026
DOM Analysisanalyzed 28/06/2026score 90/100
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://rewards-heisted.xyz/
नेमसर्वरjavier.ns.cloudflare.comrafe.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 26/06/2026scanned 28/06/2026
Case ID
ICANN OVERSIGHT

प्रत्यायन और आरएए संदर्भ

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

मान्यता एक अनुबंध है, सुरक्षा की मुहर नहीं। ICANN शुल्क सत्यापित करें RAA §3.18 पढ़ें PHISHDESTROY INVESTIGATIONICANN funding, contracts, and DNS abuse oversight
Accountability draft कुछ भी अपने आप नहीं भेजा जाता।

Latest Classified Outcome 2026-08-16 03:21:30 UTC

Primary outcome Registration hold observed reason: Registry serverHold 95% confidence
Attribution actor class: Registry mechanism: Registry serverHold source: Rdap Status Collector
Evidence layers Availability: DNS inactive Content: Unreachable DNS: NXDOMAIN Registration: Registry serverHold
Latest HTTP observation अज्ञात Origin unreachable Http 5xx 20% 2026-08-19 02:34:10 UTC
RDAP registration Registry serverHold NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 RDAP HTTP 200 source: Rdap Status Collector clientDeleteProhibitedclientTransferProhibitedserverHoldServertransferprohibited expires 2027-06-26 23:59:59 UTC checked 2026-08-16 03:21:30 UTC
Observed timeline last reachable: 2026-07-08 16:18:09 UTC current episode first observed: 2026-08-05 01:45:38 UTC observed RIP window: 2026-07-08 16:18:09 UTC → 2026-08-05 01:45:38 UTC · 657.46h midpoint estimate ≈ 2026-07-22 09:01:53 UTC · precision low · basis bounded
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

6 / 91 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed First positive detection Previous stored snapshot: 0 detections
alphaMountain.ai
Forcepoint ThreatSeeker
Fortinet
Gridinsoft
LevelBlue
SOCRadar

साक्ष्य और बाहरी रिपोर्टें

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260628-153489 Recipient: abuse@gen.xyz
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 469.5 KB

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/rewards-heisted.xyz"
  title="PhishDestroy threat report for rewards-heisted.xyz"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

एक अत्यंत सच्चा धन्यवाद-पत्र

व्यंग्यात्मक मसौदा जनरेटर

प्राप्तकर्ता
शुल्क संदर्भ

यह व्यंग्यात्मक मसौदा है। शुल्क के आंकड़े अनुमान हैं; इन्हें इस डोमेन से ठीक-ठीक जोड़ने का दावा नहीं किया जाता।